MEDIUM · 4.3

CVE-2015-0624

The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects...

Vulnerability Description

The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoContent Security Management Appliance-
CiscoWeb Security Appliance-
CiscoEmail Security Appliance Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0624?

CVE-2015-0624 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects...

How severe is CVE-2015-0624?

CVE-2015-0624 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0624?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Content Security Management Appliance, Cisco Web Security Appliance, Cisco Email Security Appliance Firmware.